


Perceptive Security
SOC/SIEM Consultancy

Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teach…
Published:
1 maart 2026 om 23:00:00
Alert date:
2 maart 2026 om 21:08:05
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A Stored XSS vulnerability exists in Chamilo learning management system's glossary function prior to version 1.11.30. The vulnerability allows users with Teachers role to inject malicious JavaScript code targeting administrators. The issue enables privilege escalation attacks where lower-privileged teachers can execute code in the context of system administrators. This represents a significant security risk in educational environments where multiple user roles interact. The vulnerability has been patched in version 1.11.30 with multiple GitHub commits addressing the issue.
Technical details
Mitigation steps:
Affected products:
Chamilo LMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-52482
https://github.com/chamilo/chamilo-lms/commit/241c569dde0ad0e34d558ae51271f70438189b0e
https://github.com/chamilo/chamilo-lms/commit/82cc07edd8ef316e6b36da7c501120d5c0aeb151
https://github.com/chamilo/chamilo-lms/commit/f9150075246df4ed9755a4a150e25edb468767be
https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.30
https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-4wcp-3rh3-7wm4
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
